
DevSecOps Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Alabama, +19 more states.
• Lead the incorporation of security into software development, continuous integration/continuous deployment (CI/CD), and cloud operations.
• Design, implement, and sustain secure CI/CD pipelines.
• Automate Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), secrets detection, security scanning, build, testing, and deployment processes.
• Architect, manage, harden, and ensure the compliance of scalable and highly available cloud infrastructure.
• Implement and oversee container security and orchestration technologies, including Docker and Kubernetes.
• Design, deploy, and manage enterprise-level secrets management solutions.
• Enforce least-privilege access through Identity and Access Management (IAM) policies and Zero Trust architecture.
• Establish continuous vulnerability assessment processes and collaborate on vulnerability triage and remediation efforts.
• Develop automated threat monitoring, anomaly detection, audit logging, and incident response capabilities.
• Stay updated with trends, standards, and best practices in DevSecOps, cloud security, and vulnerability management.
• Provide guidance, training, and mentorship on secure coding, Software Development Life Cycle (SDLC), Infrastructure as Code (IaC) security, and infrastructure practices.
• Lead alignment efforts across engineering, security, and operations teams.
• Bachelor’s degree in Computer Science, Cyber Security, Engineering, or a related field, or relevant equivalent experience.
• Over 7 years of experience in DevOps, DevSecOps, or Infrastructure Engineering with a strong emphasis on security.
• Extensive experience in integrating automated security gates into CI/CD pipelines (e.g., GitHub Actions, GitLab CI, Jenkins).
• Proficiency in scripting and automation languages (e.g., Python, Bash, Go).
• Expertise in major cloud platforms (AWS, Azure, or GCP) and cloud security tools (e.g., IAM, Security Hub, GuardDuty).
• In-depth understanding of Infrastructure as Code tools.
• Excellent communication skills, incident management capabilities, and cross-team collaboration experience.
• Experience with SAST, DAST, SCA, and secrets detection.
• Familiarity with enterprise secrets management solutions such as HashiCorp Vault or AWS Secrets Manager.
• Knowledge of IAM policies and Zero Trust architecture.
• Proven experience with continuous vulnerability assessment and remediation.
• Familiarity with cloud instances, container registries, and software dependencies.
• Experience in threat monitoring, anomaly detection, audit logging, and automating incident response.
• Abundant opportunities for career advancement.
• Comprehensive medical, dental, and vision coverage.
• 3 weeks of vacation along with 5 personal days for relaxation.
• Employee stock ownership program.
• RRSP program.
• 401k with matching contributions.
• Opportunities to contribute to community activities.
• Flexible work arrangements tailored to fit your lifestyle.
• Casual work environment.
• Opportunities for learning and development.
• An award-winning company culture.
Akamai Technologies
BeyondTrust
Cencora
PrizePicks
Get handpicked remote jobs straight to your inbox weekly.